2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19485 | CRITICAL | 9.3 | 0.2% | Aug 26, 2026 | A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versi... |
| CVE-2026-47837 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri... |
| CVE-2026-81032 | CRITICAL | 9.8 | 0.5% | Aug 26, 2026 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service d... |
| CVE-2026-80428 | CRITICAL | 9.8 | 0.7% | Aug 26, 2026 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows u... |
| CVE-2026-54569 | CRITICAL | 9.8 | 0.8% | Aug 26, 2026 | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SE... |
| CVE-2026-80589 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a neve... |
| CVE-2026-80587 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions So... |
| CVE-2026-80586 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpec... |
| CVE-2026-80585 | CRITICAL | 9.4 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN ... |
| CVE-2026-80561 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_lock... |
| CVE-2026-80558 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from prima... |
| CVE-2026-80557 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via miss... |
| CVE-2026-80554 | CRITICAL | 9.3 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program ... |
| CVE-2026-80551 | CRITICAL | 9.3 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant ... |
| CVE-2026-80528 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal... |
| CVE-2026-80519 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer re... |
| CVE-2026-75062 | CRITICAL | 9.2 | 0.2% | Aug 26, 2026 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python pr... |
| CVE-2026-74752 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When c... |
| CVE-2026-74751 | CRITICAL | 9.4 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boun... |
| CVE-2026-74746 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last... |
| CVE-2026-74744 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom... |
| CVE-2026-74743 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroo... |
| CVE-2026-74737 | CRITICAL | 9.8 | — | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extr... |
| CVE-2026-54523 | CRITICAL | 9.6 | 0.4% | Aug 26, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the Namespace... |
| CVE-2026-75896 | CRITICAL | 9.1 | — | Aug 26, 2026 | Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now